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Amendments to the Claims: 

1 . (Previously Presented): An access control system for controlling access to data stored on at 
least one data storage medium of a computing system, the access control system comprising: 

authentication means to authenticate users permitted to access data stored in the at least 

one data storage medium, the authentication means authenticating users as a super 

user or a normal user; and 
a database arranged to store a separate data access profile for each user permitted to 

access data stored in the at least one data storage medium; 
wherein each data access profile includes information indicative of the degree of access 

permitted by the user associated with the data access profile to data stored in the at 

least one data storage medium; 
wherein each data access profile includes both a master data access profile and a current 

data access profile for each user; 
wherein the master data access profile is modifiable by a super user but not by a normal 

user, and 

wherein if a first user is authenticated as a normal user, the current data access profile of 
the first user is modifiable by the first user within parameters defined by the master 
data access profile. 

2. (Original): An access control system as claimed in claim 1, further comprising profile setting 
means arranged to facilitate creation of the master and current access profiles. 

3. (Cancelled). 



4. (Previously Presented): An access control system as claimed in claim 1, wherein said access 
control system is activatable so as to permit modification of the current access profile and 
deactivatable so as to prevent modification of the current access profile. 
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5. (Original): An access control system as claimed in claim 1, wherein the access control system 
is implemented at least in part in the form of software. 

6. (Original): An access control system as claimed in claim 1, wherein the access control system 
is implemented at least in part in the form of hardware. 

7. (Original): An access control system as claimed in claim 2, wherein the access control system 
is arranged to govern user access profiles used by a security device configured to control access 
to a data storage medium. 

8. (Original): An access control system as claimed in claim 7, wherein the security device is 
implemented at least in part in hardware and is of a type located between a data storage medium 
of a computing system and a CPU of the computing system. 

9. (Original): An access control system as claimed in claim 7, wherein the security device is 
implemented at least in part in hardware and is of a type incorporated into bus bridge circuitry of 
a computing system. 

10. (Original): An access control system as claimed in claim 1, wherein the access control 
system is incorporated into a computing system having an operating system and the current access 
profile is modifiable after loading of the operating system. 

1 1 . (Currently amended): A method of controlling access to data stored on at least one data 
storage medium of a computing system using an access control system, the method comprising 
the steps of: 

configuring a separate data access profile for each user permitted to access said data, 
wherein the separate data access profile includes information indicative of the 
degree of access to said data permitted by the user, wherein each separate data 
access profile includes both a master data access profile and a current data access 
profile for each user; 
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storing said separate data access profile for each user in a database of the access control 

system; and a separate data access profile for each user permitted to access data 

stored in the at least one data storage medium ; 
authenticating a first user[[s]] permitted to access data stored in the at least one data 

storage medium as a super user or a normal user; 
wherein each data access profile includes information indicative of the degree of access 

permitted by the user associated with the data access profile to data stored in the at 

least one data storage medium; 
wherein each data access profile includes both a master data access profile and a current 

data access profile for each user; 
wherein the master data access profile is modifiable by a super user but not a normal user; 

wherein, if a first user is authenticated as a normal user, the current data access profile is 
modifiable by the first user within parameters defined by the master data access 
profile, wherein the master data access profile is modifiable by a super user but not 
a normal user . 

12-13. (Cancelled). 

14. (Currently amended): A method as claimed in claim 1 1 , further including the steps of 
facilitating activation of activating said access control system so as to permit modification of the 
current access profile and facilitating deactivation of deactivating said access control system so as 
to prevent modification of the current access profile. 

15. (Original): A method as claimed in claim 1 1, wherein the access control system is 
implemented at least in part in the form of software. 



16. (Original): A method as claimed in claim 11, wherein the access control system is 

implemented at least in part in the form of hardware. 
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17. (Original): A method as claimed in claim 11, further comprising the step of arranging 
the access control system so as to govern user access profiles used by a security device configured 
to control access to a data storage medium. 

18. (Original): A method as claimed in claim 17, wherein the security device is 
implemented at least in part in hardware and is of a type located between a data storage medium 
of a computing system and a CPU of the computing system. 

19. (Original): A method as claimed in claim 17, wherein the security device is 
implemented at least in part in hardware and is of a type incorporated into bus bridge circuitry of 
a computing system. 

20. (Currently amended): A method as claimed in claim 11, further comprising the st e ps of 
incorporating th e acc e ss control system into a wherein the computing system having has an 
operating system and f acilitating modification of the current access profile is modifiable after 
loading of the operating system. 

21 . (Currently amended): A non-transitory computer readable medium storing a computer 
program which when loaded into a computing system causes the computing system to operate in 
accordance with an access control system for controlling access to data stored on at least one data 
storage medium of a computing system, the access control system comprising: 

authentication means to authenticate users permitted to access data stored in the at least 
one data storage medium, the authentication means authenticating users as a super 
user or a normal user; and 

a database arranged to store a separate data access profile for each user; 

each data access profile being associated with a user permitted to access data stored in the 
at least one data storage medium; 
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wherein each data access profile includes information indicative of the degree of access 

permitted by the user associated with the data access profile to data stored in the at 

least one data storage medium; 
wherein each data access profile includes both a master data access profile and a current 

data access profile for each user; 
wherein the master data access profile is modifiable by a super user but not a normal user; 

and 

wherein if a first user is authenticated as a normal user, the current data access profile of 
the first user is modifiable by the first user within parameters defined by the master 
data access profile. 

22. (Previously Presented): A non-transitory computer readable medium having a program code 
embodied therein for causing a computer to operate in accordance with an access control system 
for controlling access to data stored on at least one data storage medium of a computing system, 
the access control system comprising: 

authentication means to authenticate users permitted to access data stored in the at least 
one data storage medium, the authentication means authenticating users as a super 
user or a normal user; and 
a database arranged to store a separate data access profile for each user; 
each data access profile being associated with a user permitted to access data stored in the 

at least one data storage medium; 
wherein each data access profile includes information indicative of the degree of access 

permitted by the user associated with the data access profile to data stored in the at 
least one data storage medium; 
wherein each data access profile includes both a master data access profile and a current 

data access profile for each user; 
wherein the master data access profile is modifiable by a super user but not a normal user; 
and 

wherein if a first user is authenticated as a normal user, the current data access profile of 
the first user is modifiable by the first user within parameters defined by the master data 
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access profile. 



